BIOC Informational

User creation or modification via /etc file

Attackers may create new users or modify existing users by directly modifying /etc/passwd and /etc/shadow.

Module:
Platform Analytics
Agent event type:
File
Category:
Persistence
Status:
Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Create Account (T1136)
Indicator:

File file path = /etc/shadow , /etc/passwd AND action type = write

Preventable: yes